The project is small and maintained by one person, with no security scanning or policy. It is clearly licensed, documented, correctly linked to its repository, and has no install-time scripts.
58%
Total Score
50
100
90
75
One registry maintainer is consistent with a small user-owned project, but it provides little redundancy if that person stops maintaining it.
The latest release was over two years ago, and there were no releases in the last 12 months. The five-release history shows a slow cadence, which raises maintenance risk for a database integration.
The repository recorded no commits and had no active maintainers in the last three months. Combined with the long release gap, this suggests the project may be dormant.
There were no new or closed issues or pull requests in the last month, while five issues and one pull request remain open. This is modest evidence of limited ongoing attention.
The repository has no security policy or security scanning tools. This is a transparency and maintenance gap, though it does not by itself indicate that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.